Deploying Wazuh agents on Linux endpoints
The Wazuh agent runs on the endpoint you want to monitor and communicates with the Wazuh manager, sending data in near real-time through an encrypted and authenticated channel.
Install the Wazuh agent from the Wazuh repository. The WAZUH_ENROLLMENT_TOKEN and WAZUH_AGENT_NAME variables in the install command enroll the agent with the Wazuh manager when it first starts. To download the package instead, see Packages list.
Before you start, create an enrollment token on the Wazuh manager, as described in Generate the enrollment token. The endpoint must reach the Wazuh manager on port 1517/TCP.
Note
Run the commands below as root. If you use sudo, put the variables after it, for example sudo WAZUH_ENROLLMENT_TOKEN='<ENROLLMENT_TOKEN>' WAZUH_AGENT_NAME='<AGENT_NAME>' apt-get install -y wazuh-agent, because sudo doesn't pass your environment variables to the command.
Add the Wazuh repository
Add the Wazuh repository to download the official packages.
Use the tab of your system's package manager: DNF on Red Hat Enterprise Linux 8 and later and compatible systems, Yum on systems without DNF, ZYpp on SUSE, and APT on Debian and Ubuntu.
Install the following packages if missing:
# apt-get install -y gnupg apt-transport-https curl
Install the GPG key:
# curl -s https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH | gpg --no-default-keyring --keyring gnupg-ring:/usr/share/keyrings/wazuh.gpg --import && chmod 644 /usr/share/keyrings/wazuh.gpg
Add the repository:
# echo "deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/apt/ unstable main" | tee /etc/apt/sources.list.d/wazuh.list
Update the package information:
# apt-get update
Import the GPG key:
# rpm --import https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH
Add the repository:
# echo -e '[wazuh]\ngpgcheck=1\ngpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH\nenabled=1\nname=EL-$releasever - Wazuh\nbaseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/\nprotect=1' | tee /etc/yum.repos.d/wazuh.repo
Import the GPG key:
# rpm --import https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH
Add the repository:
# echo -e '[wazuh]\ngpgcheck=1\ngpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH\nenabled=1\nname=EL-$releasever - Wazuh\nbaseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/\npriority=1' | tee /etc/yum.repos.d/wazuh.repo
Import the GPG key:
# rpm --import https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH
Add the repository:
# cat > /etc/zypp/repos.d/wazuh.repo <<\EOF [wazuh] gpgcheck=1 gpgkey=https://packages-staging.xdrsiem.wazuh.info/key/GPG-KEY-WAZUH enabled=1 name=Wazuh repository baseurl=https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/yum/ EOF
Refresh the repository:
# zypper refresh
Deploy a Wazuh agent
Follow these steps to deploy the Wazuh agent on your Linux endpoint.
Select your package manager and run the following command. Replace
<ENROLLMENT_TOKEN>with the token you created in Generate the enrollment token, and<AGENT_NAME>with a name for this endpoint that no other agent uses, for example, its host name. If you omitWAZUH_AGENT_NAME, the agent enrolls under the host name. The Wazuh manager refuses a name that another agent already uses.# WAZUH_ENROLLMENT_TOKEN='<ENROLLMENT_TOKEN>' WAZUH_AGENT_NAME='<AGENT_NAME>' apt-get install -y wazuh-agent
# WAZUH_ENROLLMENT_TOKEN='<ENROLLMENT_TOKEN>' WAZUH_AGENT_NAME='<AGENT_NAME>' yum install -y wazuh-agent
# WAZUH_ENROLLMENT_TOKEN='<ENROLLMENT_TOKEN>' WAZUH_AGENT_NAME='<AGENT_NAME>' dnf install -y wazuh-agent
# WAZUH_ENROLLMENT_TOKEN='<ENROLLMENT_TOKEN>' WAZUH_AGENT_NAME='<AGENT_NAME>' zypper install -y wazuh-agent
For additional deployment options such as agent group, see the Deployment variables section. Enable and start the Wazuh agent service:
# systemctl daemon-reload # systemctl enable wazuh-agent # systemctl start wazuh-agent
Choose one option according to your operating system.
RPM-based operating systems:
# chkconfig --add wazuh-agent # service wazuh-agent start
Debian-based operating systems:
# update-rc.d wazuh-agent defaults 95 10 # service wazuh-agent start
On some systems, you need to start the Wazuh agent manually:
# /var/ossec/bin/wazuh-control start
Check that the Wazuh agent is enrolled and connected:
# grep ^status /var/ossec/var/run/wazuh-agentd.state # grep 'Token bootstrap: enrollment succeeded' /var/ossec/logs/ossec.log
The first command prints
status='connected'. If it printsstatus='pending', wait a few seconds and run it again. The second prints a line that ends inToken bootstrap: enrollment succeeded; the manager's CA is now the agent's trust anchor.In the Wazuh dashboard, Agents management > Summary lists the agent as Active.If
systemctl start wazuh-agentfailed or the agent didn't enroll, the cause is one of these:The install command printed
no manager configured [INFO_NO_MANAGER]: the token didn't reach the installer, for example becausesudodropped it.The install command printed
deployment variables refused [ERR_BAD_TOKEN]: the token changed when you copied it./var/ossec/logs/ossec.logshowsEnrollment-token bootstrap failed: the Wazuh manager refused the token, for example because it was revoked, it expired, or it was already used as many times as--max-usesallows.
In each case, save a valid token to a file, enroll the agent, delete the file, and start the agent. In the first two cases, the installer kept no agent name, so the agent enrolls under the endpoint's host name.
# /var/ossec/bin/wazuh-agent-auth --token-file <TOKEN_FILE_PATH> # rm -f <TOKEN_FILE_PATH> # systemctl start wazuh-agent
The deployment process is now complete, and the Wazuh agent is successfully running on your Linux endpoint.
Disable Wazuh updates
Compatibility between the Wazuh agent and the Wazuh manager is guaranteed when the Wazuh manager version is later than or equal to that of the Wazuh agent. Therefore, we recommend disabling the Wazuh repository to prevent accidental upgrades. To do so, use the following command:
# sed -i "s/^deb /#deb /" /etc/apt/sources.list.d/wazuh.list
# apt-get update
Alternatively, you can set the package state to hold. This action stops updates. To upgrade or uninstall the Wazuh agent later, run apt-mark unhold wazuh-agent first.
# echo "wazuh-agent hold" | dpkg --set-selections
# sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo
# sed -i "s/^enabled=1/enabled=0/" /etc/yum.repos.d/wazuh.repo
# sed -i "s/^enabled=1/enabled=0/" /etc/zypp/repos.d/wazuh.repo